CVE-2026-21962, a maximum-severity improper access control flaw in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in (CVSS 10.0), has been added to CISA's Known Exploited Vulnerabilities catalog following confirmed active exploitation. The vulnerability allows unauthenticated attackers with network access via HTTP to unauthorizedly access, modify, or delete critical data. Patches were released in January 2026, and exploitation attempts have been documented by GreyNoise and CloudSEK.
A 2025 Oracle Health/Cerner data breach has now been disclosed as affecting 28 hospitals and health systems. The breach exposed patient and organizational data across a significant portion of healthcare providers relying on Oracle Health's EHR platform, representing one of the largest healthcare data compromises linked to this vendor.
Oracle's July 2026 Critical Patch Update permanently fixed CVE-2026-35273, a privilege-escalation zero-day in PeopleSoft PeopleTools (CVSS 9.8) that ShinyHunters actively exploited to breach over 100 organizations worldwide—primarily universities—between May 27 and June 9, 2026. The vulnerability enabled unauthenticated remote code execution; 68% of affected organizations were higher-education institutions, with confirmed data exposures including 40+ gigabytes from University of Nottingham covering nearly 500,000 students. Oracle issued an out-of-band alert on June 10 after exploitation was already underway for two weeks, underscoring disclosure delays in critical enterprise software.
Oracle released its July 2026 Critical Patch Update on July 22, 2026, shipping 1,449 patches addressing over 1,200 vulnerabilities across 30+ product families including Database, Fusion Middleware, MySQL, E-Business Suite, JD Edwards, and Oracle Communications. A significant share are remotely exploitable without authentication and enable RCE, privilege escalation, or data breach. AI systems were used extensively to accelerate vulnerability discovery.
CISA added CVE-2026-46817, a critical improper privilege management vulnerability in Oracle E-Business Suite's Oracle Payments component, to its Known Exploited Vulnerabilities catalog on July 15, 2026. The flaw allows unauthenticated attackers with HTTP network access to fully compromise Oracle Payments systems without authentication. Active exploitation has been confirmed in the wild. CISA ordered federal agencies to patch by July 18, 2026; Oracle issued fixes in its May 2026 Critical Security Patch Update.
Oracle Health's legacy Cerner systems experienced a data breach in January 2025 affecting patient data at at least 17 hospitals across the United States, including Sharp Tri-City Medical Center, AdventHealth, Baptist Health South Florida, and others. Notification to affected patients has been ongoing through July 2026, with health systems completing their own investigations and legal action underway alleging Oracle Health failed to adequately protect patient data and delayed notification.
A critical vulnerability (CVE-2026-46817) in Oracle E-Business Suite is under active exploitation in the wild. Approximately 900–950 internet-facing EBS instances have been identified globally, with DefusedCyber observing real-world attack attempts. The flaw enables remote code execution and affects systems handling sensitive financial, HR, and operational data. Attackers appear to have reverse-engineered Oracle's patch before public disclosure.
Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 contain a critical remote code execution vulnerability (CVE-2026-35273) in the Updates Environment Management component. The vulnerability allows unauthenticated remote attackers to execute arbitrary code via HTTP. Exploitation is actively occurring in the wild; immediate patching is required.
ShinyHunters claimed breach of Oracle PeopleSoft servers at over 100 organizations including universities, exfiltrating student records, financial aid data, and administrative information. The group exploited a vulnerability in PeopleSoft to achieve mass compromise; attackers obtained personal data including home addresses, phone numbers, emails, and dates of birth from educational institutions.
CVE-2026-46839, a critical vulnerability in Oracle REST Data Services (ORDS) Core component, allows low-privileged authenticated attackers to execute arbitrary code and gain full system control via path traversal. Affects versions 24.2.0–26.1.0 with CVSS 9.9. Oracle released a patch in May 2026; exploitation complexity is low and no public PoC exists as of early June 2026, but technical details suggest rapid weaponization is likely.
CISA added CVE-2024-21182, a critical Oracle WebLogic Server vulnerability, to its Known Exploited Vulnerabilities catalog on June 1, 2026, after confirming active exploitation in the wild. The flaw allows unauthenticated attackers to gain unauthorized access via T3 and IIOP protocols. CISA ordered federal agencies to patch by June 4, 2026, and strongly recommends organizations apply mitigations immediately to prevent compromise of WebLogic-dependent services including potential Oracle Health infrastructure.